A real audit answer
The branch can show precisely when and how a specific customer agreed to receive marketing email, instead of relying on an informal register with no recorded consent basis behind it at all.
Available now
In build
The whole team
Nineteen specialists, each with a defined job and an honest status label.
See all nineteenThe business can show, for any contact on its list, exactly when and how that person agreed to receive marketing email — protecting it from spam complaints and regulatory risk.
Works with
What it does
Patri records the source, timestamp and method of consent every time a contact joins a list, whether through a signup form, a manual add or an import, and supports a double opt-in confirmation step for stricter compliance. The owner can see a consent record for any contact on request.
A regional NBFC branch has collected customer email addresses for years, in a register nobody formalised into an actual consent record — just a column asking for an email, with no note of whether the customer agreed to marketing or simply gave the address for statements. When an audit later asks the branch to show consent for a rate-update campaign, there is nothing concrete beyond 'we have had their email a long time'.
Consent and opt-in capture closes that gap by recording the source, timestamp and method of consent every time a contact joins a list — a signup form, a manual add, an import — and supports a double opt-in confirmation step for stricter proof. Any contact's consent history is visible on request, so the branch, or any business, can show exactly when and how a specific person agreed to be emailed, rather than reconstructing a story after the fact.
Patri runs this directly on the platforms your customers already use — no separate app for them to install.
How it works
A signup form submission, a manual add by staff, or a CSV import each writes a record capturing the source, timestamp, method and the notice version the person actually saw at that exact moment in time.
For businesses wanting stronger proof, a first opt-in triggers a confirmation email the person has to actively click before they are fully added, with a single reminder sent if they have not yet confirmed it.
Anyone uploading a batch of contacts has to state the actual consent basis for that specific batch before the import proceeds, rather than the system assuming an email address alone is sufficient grounds to add someone.
For any individual on the list, the exact source, date and method of their consent can be pulled up immediately, which is exactly what an audit, a regulator or the customer themselves might reasonably ask to see.
Why it matters
The branch can show precisely when and how a specific customer agreed to receive marketing email, instead of relying on an informal register with no recorded consent basis behind it at all.
Requiring a captured affirmative action before someone joins a marketing list means fewer recipients who genuinely never consented, which is exactly the group most likely to complain or report spam.
Consent history sits with the contact record permanently, so answering 'did this person actually agree to this' never depends on someone's memory of what happened months or years ago.
The detail
India's DPDP Act 2023 sets a specific bar for valid consent: it has to be free, specific, informed, unconditional and unambiguous, given through a clear affirmative action. A pre-checked box that assumes agreement unless unchecked does not meet that bar, nor does inferring marketing consent from an unrelated action, such as giving an email address purely to receive a statement. A contact cannot be added to a marketing list here without a captured affirmative action recorded against them, because anything looser is not consent under the law that governs it.
Bulk imports are the highest-risk path for consent violations, by a wide margin, because they add many contacts at once with no individual affirmative action happening inside this product — the action, if it happened at all, happened elsewhere, outside this system's view. This is why an import requires the uploader to attest to the consent basis for that batch before it proceeds; the tool cannot verify consent independently, but can refuse to treat 'we have their email address' as equivalent to a marketing opt-in, which it plainly is not.
The notice shown at signup matters as much as the click itself. DPDP notice requirements expect plain, simple language describing what data is collected and why, and because that text can reasonably change as practices evolve, the specific version a contact saw when they consented is stored against their record. A business relying on this still has to write that notice honestly; capturing which version was shown protects the record, but does not substitute for the notice being adequate.
Industry use cases
13 industries where Patri applies this directly.
A dealership's website inquiry form feeds new leads into a segmented list; Patri sends a short nurture sequence over the following two weeks and a service-due reminder automation runs quietly in the background for existing customers.
See the automotive playbookA software reseller captures demo requests through a signup form; Patri enrolls each lead in a welcome-and-nurture automation while the sales manager reviews and approves the first broadcast to a larger prospect list before it sends.
See the b2b sales playbookA regional NBFC branch collects customer email consent at account opening; Patri stores that consent record and later sends a fixed-deposit rate update only to customers whose consent record is on file, routed through a manager approval step first.
See the banking and finance playbookA D2C skincare brand connects its online store; when a shopper adds a serum to cart but leaves, Patri's recovery automation sends a reminder a few hours later without any manual action from the brand's small team.
See the beauty and cosmetics playbookAn online exam-prep platform enrolls every new trial signup into a welcome series that introduces study resources over the first week, while a separate automation checks in on students who have not logged in for two weeks.
See the education playbookAn independent designer adds a signup form to their portfolio page; Patri captures each new subscriber's consent and sends a two-email welcome sequence introducing recent work.
See the freelancers and consultants playbookA physiotherapy clinic uses a welcome sequence for new patient inquiries and a quarterly newsletter reviewed by the clinic owner before sending, since Patri flags AI-drafted health claims for manual approval.
See the health and wellness playbookA modular-furniture retailer connects its catalogue site; a visitor who views a wardrobe configuration but does not request a quote receives a follow-up email a day later through Patri's recovery automation.
See the home decor and furnishing playbookAn agency managing five retail clients keeps each client's contact list and consent records separate in Patri, with every draft campaign routed through the account manager's approval before it reaches that client's subscribers.
See the marketing agencies playbookA brokerage captures site-visit inquiries through a signup form; Patri enrolls each inquiry in a nurture sequence that shares similar listings over the following weeks, while a broadcast to the full buyer list still needs the principal broker's sign-off.
See the real estate playbookA restaurant collects email addresses through a QR-code signup form at checkout; Patri sends a monthly offer email to that list and automatically suppresses anyone who unsubscribes from future sends.
See the restaurants and food playbookA salon connects its booking system; clients with no visit in the last two months are automatically enrolled in Patri's re-engagement sequence, which pauses immediately if the client books a new appointment.
See the spas and salons playbookA travel agency's package-inquiry form feeds into Patri, which sends a short sequence of destination highlights over the following days and a follow-up if the traveler started but did not finish a booking request.
See the travel and tourism playbookMore from Patri
The business gets a professional-looking email out to its list without hiring a designer or writing code.
Learn moreThe business sends fewer, more relevant emails and avoids annoying subscribers who do not care about a given message.
Learn moreThe business nurtures leads and customers on autopilot — a welcome series, a re-engagement sequence — without anyone remembering to hit send each day.
Learn moreNew subscribers and customers get an immediate, on-brand introduction instead of silence after they sign up.
Learn moreThe business wins back revenue and engagement from people who started something (a cart, a booking, an inquiry) and did not finish.
Learn moreThe business finds out which subject line or message performs better before committing the whole list to one version.
Learn moreQuestions
Not without separate, specific consent for marketing — under the DPDP Act, consent has to be specific to what it covers, so an email collected for statements is not automatically valid grounds for a promotional campaign. The branch would need to capture a distinct, affirmative opt-in for marketing communications before adding that customer to a promotional list, even though the email address itself is already on file for another purpose.
No — DPDP requires a clear affirmative action, and a box that is checked by default and simply left unchecked by an uninterested customer does not represent that person actively choosing to opt in. A valid consent record needs the person to have actively ticked or selected the option themselves, not merely failed to remove a default selection they may not have even noticed.
The import requires whoever is uploading the batch to attest to the actual consent basis behind that specific list before the import proceeds — the system does not simply assume that having an email address is equivalent to marketing consent. If there is no genuine consent basis for that old spreadsheet, it should not be imported for marketing purposes regardless of how long the business has held those contacts on file.
Yes — every contact's consent record shows the source, timestamp and method of their opt-in, along with which version of the consent notice they were shown at that moment, all viewable on request for any individual contact on the list. This is precisely the kind of specific record an internal audit or a regulator would reasonably expect a business to be able to produce.
The rest of your stack
No rip-and-replace — prove every contact agreed to be emailed works alongside the systems already running your business.
Coming soon